Knowledgebase

Windows Server and Active Directory: Everything That Matters, Briefly Print

  • microsofttechnology, microsoft, domain, backup, hacked, dns, downtime, permissions
  • 0

The summary.

DOMAIN MEMBERS MUST USE INTERNAL DNS

Pointing them at public servers breaks authentication and policy in ways that appear unrelated. It is the commonest misconfiguration in these environments.

RUN AT LEAST TWO DOMAIN CONTROLLERS, AND MONITOR REPLICATION

One is a single point of failure for all authentication, and replication fails silently.

COMPROMISE OF THE DIRECTORY IS COMPROMISE OF EVERYTHING

Separate administrative accounts from daily use, restrict where they may sign in, and never expose high-value credentials on lower-value machines — they are harvested from compromised workstations.

ASSIGN PERMISSIONS TO GROUPS, AND DESIGN SO INHERITANCE GIVES THE RIGHT RESULT

Breaking inheritance produces structures nobody can reason about.

KEEP ONE BACKUP COPY UNREACHABLE FROM THE NETWORK

Ransomware seeks and destroys reachable backups, and backup credentials should never be domain administrator.

PRACTISE DIRECTORY RECOVERY

It is complex, and nobody attempts it until it is required.

MOVING A SERVER TO THE CLOUD AS IT IS CARRIES ALL ITS MAINTENANCE WITH IT

Prefer a managed service or replacement where practical.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot